LightLLM hit by two CVSS 9.8 unauthenticated RCE flaws
Two unauthenticated CVSS 9.8 RCE vulnerabilities (CVE-2026-103040 and CVE-2026-103041) were found in the LightLLM serving framework via pickle deserialization in RPyC services, plus a 7.5-rated DoS (CVE-2026-103042). No patch is confirmed and all versions through 1.2.0 are affected.
- CVE-2026-103040 and CVE-2026-103041 are CVSS 9.8 RCEs via pickle.loads in RPyC
- CVE-2026-103042 is a 7.5 memory-exhaustion DoS on the NCCL channel
- All LightLLM versions through 1.2.0 are affected
- No patch yet; disable --enable_profiling and firewall RPyC ports
Read next
Security